Skip to content

Bump trivy to 0.69.2#2187

Merged
priteau merged 1 commit intostackhpc/2025.1from
bump-trivy
Mar 2, 2026
Merged

Bump trivy to 0.69.2#2187
priteau merged 1 commit intostackhpc/2025.1from
bump-trivy

Conversation

@seunghun1ee
Copy link
Copy Markdown
Member

@seunghun1ee seunghun1ee commented Mar 2, 2026

Trivy had security incident on 1st March 2026 [1], resulting losing all
GitHub Releases between 0.27.0-0.69.1.
They then restored the latest as 0.69.2

[1] https://github.com/aquasecurity/trivy/discussions/10265

@priteau
Copy link
Copy Markdown
Member

priteau commented Mar 2, 2026

There are two occurrences to bump each time, the other one is in tools/scan-images.sh.

@seunghun1ee
Copy link
Copy Markdown
Member Author

The version number on tools/scan-images.sh is just a message. I'll change that too after the test at https://github.com/stackhpc/stackhpc-kayobe-config/actions/runs/22570327495

Trivy had security incident on 1st March 2026 [1], resulting losing all
GitHub Releases between 0.27.0-0.69.1.
They then restored the latest as 0.69.2

[1] https://github.com/aquasecurity/trivy/discussions/10265
@seunghun1ee
Copy link
Copy Markdown
Member Author

Test CI run shows that the images were scanned well.

@priteau priteau merged commit 92ec1f4 into stackhpc/2025.1 Mar 2, 2026
21 of 22 checks passed
@priteau priteau deleted the bump-trivy branch March 2, 2026 11:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants